Wind River Support Network

HomeDefectsLIN1021-4188
Fixed

LIN1021-4188 : Security Advisory - hdf5 - CVE-2022-26061

Created: Aug 22, 2022    Updated: Feb 9, 2023
Resolved Date: Feb 9, 2023
Found In Version: 10.21.20.1
Fix Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CREATE(Triage):(User=admin) CVE-2022-26061 (https://nvd.nist.gov/vuln/detail/CVE-2022-26061)

CVEs


Live chat
Online